chapter 6 cybercrimes. spam good marketing points? cheap highly effective pgp busa331 chapter 82

51
Chapter 6 Cybercrimes

Upload: taryn-mitchiner

Post on 15-Dec-2015

218 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

Chapter 6Cybercrimes

Page 2: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

2

Spam

• Good marketing points?• Cheap• Highly effective

PgP BUSA331 Chapter 8

Page 3: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

3

Spam

• Bad points?• Makes up 90% of U.S. e-mail!

PgP BUSA331

Page 4: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

4

Spam Avoidance

• Never reply• Do not put email address on web site• Use alias email address in newsgroups• Do not readily give out email address• Use spam filter• Never buy from spam

PgP BUSA331

Page 5: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

5

CAN-SPAM

• Controlling Assault of Non-Solicited Pornography and Marketing Act• Does not ban sending spam• Due to 1st Amendment, free speech

• Some states have more restrictive laws

PgP BUSA331

Page 6: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

6

CAN-SPAM Requires

• Accurate email headers, valid return address• Opt-out procedures• Why not opt-in?

• Clear notice of opt-out• Compliance with opt-out within 10 days• Label commercial email as solicitation• Sender’s valid physical address• Warning labels on sexually oriented material

PgP BUSA331

Page 7: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

7

CAN-SPAM Prohibits

• Misleading subject lines• Email address harvesting

PgP BUSA331

Page 8: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

8

CAN-SPAM Enforcement

• FTC • AGs (Attorneys General)• ISPs• No private right of action

PgP BUSA331

Page 9: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

9

CAN-SPAM Prosecutions

• Illinois, Florida, New York, California• Bottom line-has done little to impede the spam

onslaught

PgP BUSA331

Page 10: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

10

State SPAM Laws

• Patchwork, non uniform• Jurisdictional questions• Opt-in requirements• Limited by first amendment issues

PgP BUSA331

Page 11: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

11

Foreign SPAM Laws

• Main issue is enforcement

PgP BUSA331

Page 12: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

12

Fighting SPAM

• FTC-Federal Trade Commission, truth in advertising laws• Trademark infringement • RICO-Racketeer Influenced and Corrupt

Organizations Act• Computer Fraud and Abuse Act, unauthorized

computer use to get email addresses

PgP BUSA331

Page 13: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

13

Murking

• Bills vs Laws

PgP BUSA331

Page 14: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

14

Mail Bombs

• Excessive email to overload server storage• Denial of service attack

PgP BUSA331

Page 15: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

15

Permission Based Marketing• Legal, because requested• Opt-in• RSS feed sign up…

PgP BUSA331

Page 16: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

Chapter 9Social Engineering and Identity Theft

Page 17: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

17

Ultimate Goal

• Steal Passwords, Personally Identifiable Information- Your ‘Identity’• In order to profit• Internet enables this without physical contact

PgP BUSA331

Page 18: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

18

Email Spoofing

• Forge email header• Appears email came from other than true sender• Why spoof?• Avoid identification under spam laws• Hide identity, avoid liability for illegal activity• Download Trojans to control computers• Obtain confidential information

PgP BUSA331

Page 19: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

19

Phishing

• Use of official looking emails to trick people into revealing• Usernames• Passwords• Other Personally Identifiable Information

• Result- loss of confidence in web transactions

PgP BUSA331

Page 20: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

20

Ice Phishing?

• No, but there is…• Personalized Phishing-target victim by name,

already have some info, hoping to get more• Spear Phishing-Pose as high level executive,

demand info• Effective against soldiers

• Whaling-Target high level executives• Lesson-think twice before clicking IM or email

hyperlink!

PgP BUSA331

Page 21: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

21

Pharming

• Similar to phishing• Use web sites to obtain personal info• DNS exploits

PgP BUSA331

Page 22: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

22

Identity Theft

• Goal-obtain key personal info• Falsely obtain goods & services• Sources• Database cracking• Social engineering• Pretexting• Survey

• Results-large $ loss• But credit cards safer on web

PgP BUSA331

Page 23: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

23

Social Security Numbers

• de facto national identifier• Key to a person’s identity• SSNs can be found online in government records

PgP BUSA331

Page 24: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

24

Personal Information Safeguard• Dumpster diving• Shred your garbage?

• Be mindful of https• Review credit reports• Do not reveal SSN unless a must• Wary of giving personal info• Overwrite old hard drives• Copy machine hard drives?

PgP BUSA331

Page 25: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

25

Identity Theft Penalty Enhancement Act• Sounds good-mandatory jail time for possessing

identity info with intent of committing crime• Real issue-hold info handlers accountable for data

they collect

PgP BUSA331

Page 26: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

26

CAAS?

• Have you heard of Software as a Service-SAAS? A hot new trend in technology• How about CAAS?• Crimeware as a Service

• Criminals Never Stop Innovating

PgP BUSA331

Page 27: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

Chapter 10Cybercrimes Using Technology

Page 28: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

28

Targets

• Computers (like yours!)• Internet Connection

PgP BUSA331

Page 29: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

29

Terminology

• Beware-cybercrime terms (trojan, virus, malware…) often used interchangeably, but they are different

PgP BUSA331

Page 30: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

30

Computer Cybercrime-Cookie Poisoning• Cookies-data to enhance web browsing experience• Cookie downside-tracking• Cookie poisoning-attacker modifies cookie• For protection, encrypt cookies

• Cookie Background at GRC

PgP BUSA331

Page 31: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

31

Computer Cybercrime-Spyware• Tracks and forwards data without user consent• Uses computer for malicious purposes• Also slows performance, crashes computer• FTC investigates, has prosecuted under federal

computer privacy laws• Sears has used spyware on customers-oops• Steal user stock account login

• Sell portfolio• Manipulate stocks using account

• Avoid public computers, change passwords oftenPgP BUSA331

Page 32: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

32

Computer Cybercrime-Drive-by Download• Program download without consent• Viewing web site or email

• Similar to spyware• Form of computer trespass• Avoid by using security software

PgP BUSA331

Page 33: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

33

Computer Cybercrime-Malware• Virus-copies itself, infects computer• Worm-self replicating virus• Trojan horse-malicious program within harmless

program, like spyware-non-self-replicating• Used to take control

PgP BUSA331

Page 34: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

34

Internet Connection Cybercrime-Wardriving• Using Wi-Fi laptop to map Wireless Access Points• Subsequent use of Internet connection is

telecommunications theft.

PgP BUSA331

Page 35: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

35

Internet Connection Cybercrime-Piggy-backing• Using wireless internet connection without

permission• State laws vary• Countries vary

PgP BUSA331

Page 36: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

36

Internet Connection Cybercrime-Issues• Others use your internet connection to commit

cybercrimes• Downloading child pornography

• Is a business liable for the unauthorized use of their unsecured wireless internet connection to commit a crime?• Courts not yet involved• Solution-secure / encrypt wireless access!

PgP BUSA331

Page 37: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

37

What’s Next?

• Electromagnetic Keyboard Sniffing• Steal computer keypress/keystrokes from 65 feet away

wirelessly!• http://en.wikipedia.org/wiki/Keystroke_logging#Electro

magnetic_emissions

PgP BUSA331

Page 38: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

Chapter 11Cybercrimes and Individuals

Page 39: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Mule Scam

• Victim/mule (usually unknowingly) helps launder stolen online funds• Uses mule’s PayPal account to transfer defrauded

victim’s funds, • Mule paid commission from % of defrauded victim’s

funds• Defrauded victim contacts mule seeking funds back• eBay will require mule to pay innocent defrauded

victim

Page 40: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Cyberstalking

• Using email, IM, blog… to harass victim• Also incite others against victim• Can be combined with real world stalking

Page 41: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Corporate Cyberstalking

• Corporation stalking ex customer or ex employee• Or vice versa, but less likely

Page 42: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Cyberstalking Law

• No federal law• State law varies• Harassment vs stalking• Harassment barred by 41 states

Page 43: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Federal Statutes-Securities

• Spam, message boards and chat rooms used to hype stocks, trying to manipulate prices• Also violate state securities laws• SEC estimates 100 million stock spam messages per

week• IPO quiet time (90 day) can be violated by blog or

tweet

Page 44: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

USA PATRIOT Act

• Rushed response to 9/11 attacks• Amended many federal statutes• Civil liberty protections suffered• Lessened standard for government to intercept

electronic messages• Broad reach, beyond terrorists

Page 45: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

USA PATRIOT Act

• Subpoena of bank account and credit card numbers from ISPs• Request ISP to release customer info voluntarily• Danger in government labeling someone terrorist• Expansive search warrant powers• Secret ‘National Security Letters’ without court

order!• Declared unconstitutional in 2004

• FBI eavesdrops on computer traffic

Page 46: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Online Gambling

• Est 2006 revenue-$12 billion• Est 2010 revenue-$25 billion-half from U.S.• State regulated• Internet issues- may be legal in other locations, but

not where bet is placed• Eight states outlaw online gambling• British online gambling execs arrested on U.S. soil

Page 47: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Gambling Types

• Casino• Sports

Page 48: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

International Level

• No agreement, legal is some countries• Countries complain about U.S.• WTO declares U.S. out of compliance• Either let citizens gamble online• Or total ban (including lottery tickets)

Page 49: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Wire Wager Act of 1961

• Prohibits use of wire transmission in interstate or foreign commerce of bets, wagers, information on them• Government must prove• Engaged in gambling• Interstate transmission of bets…• Used wire communication facility• Acted knowingly

Page 50: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Unlawful Internet Gambling Enforcement Act-2006• Congress goes after money, not gamblers• Illegal to process gambling payments• But U.S. gamblers may use off-shore payment

processors

Page 51: Chapter 6 Cybercrimes. Spam Good marketing points? Cheap Highly effective PgP BUSA331 Chapter 82

PgP BUSA331

Virtual Crime

• Online multiplayer environments• Habbo• Second Life

• Virtual goods, so virtual or actual theft?• Physical coercion to obtain virtual artifacts• Second Life does $1Million/day of commerce!• Will only get worse…